Minimega
sandia-minimega/minimega
This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…
A skill your agent uses when taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third), then wiring container → CI → registry → host with…
$ npx skills add ericrisco/rsc-harness --skill deployment -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness deployment --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deployment .claude/skills/deployment && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deployment" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/deployment into .claude/skills/deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deployment", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/deploymentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill deployment -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness deployment --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/deployment .agents/skills/deployment && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deployment" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/deployment into .agents/skills/deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deployment", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill deployment -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness deployment --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/deployment .cursor/skills/deployment && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deployment" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/deployment into .cursor/skills/deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deployment", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/deployment--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill deployment -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness deployment --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/deployment .gemini/skills/deployment && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deployment" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/deployment into .gemini/skills/deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deployment", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness deploymentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill deployment -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/deployment .github/skills/deployment && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deployment" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/deployment into .github/skills/deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deployment", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill deployment -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness deployment --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/deployment .opencode/skills/deployment && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deployment" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/deployment into .opencode/skills/deployment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deployment", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deploymentA skill your agent uses when taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third), then wiring container → CI → registry → host with…
Deployment is an agent skill from ericrisco/rsc-harness. Use when taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third), then wiring container → CI → registry → host with build secrets, healthchecks and rollback. NOT one platform's mechanics (that is coolify, vercel, railway, render), NOT the Dockerfile alone (that is docker).
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/coolify.md`).
It sits in DevOps & Cloud, covering Containers and Deployment. It works with Docker, Vercel, PostgreSQL and Python. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
dockercurltrivyhadolintbashFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENNPM_TOKENPOSTGRES_PASSWORDCOOLIFY_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deployment loads about 4.2k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,314 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
.env*| Secrets in `compose.yaml` env | `.env` (gitignored) / Coolify secret env |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,314 words, ~4,166 tokens.
.claude/skills/deployment/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Take any app in this repo from source → hardened container → green CI/CD → live on the right host, with secrets that never leak into image layers or logs, and a defined rollback path.
source → Dockerfile (multi-stage) → CI (lint·test·build·scan) → registry (ghcr) → target (Coolify·Vercel·Hetzner, rolling) → live + rollback
▲
choose via references/hosting-targets.mdOut of scope — say so and stop: Kubernetes / Helm / ECS / Nomad orchestration; cloud IaC (Terraform, Pulumi, CloudFormation — only the GHA↔cloud OIDC handshake is covered, not provisioning); application runtime code and DB schema/migration logic (the per-stack skills at the bottom own what runs inside the container).
Consult these first. They settle 90% of choices before you write a line.
Table A — Base image by stack
| Stack | Base image | Notes |
|---|---|---|
| FastAPI / Python | gcr.io/distroless/python3-debian12:nonroot (or python:3.13-slim) | UID 65532, no shell |
| Go | gcr.io/distroless/static-debian12:nonroot | CGO_ENABLED=0 static, ~10 MB |
| Next.js | node:24-bookworm-slim | Active LTS; output: "standalone" |
| Flutter web | nginxinc/nginx-unprivileged:1.27-alpine | static SPA + try_files fallback |
| Postgres | postgres:18-alpine | managed/official — do NOT build a custom image |
Table B — Coolify build pack
| Situation | Pick |
|---|---|
| Repo has a Dockerfile | Dockerfile pack (always — CI/prod parity) |
| No Dockerfile, standard stack | Nixpacks / Railpack |
| Static SPA, no server | Static |
| Multi-service local parity | Docker Compose |
| CI already builds & pushes | Docker Image (deploy prebuilt ghcr image) |
If it has a Dockerfile, use the Dockerfile pack.
Table C — Deploy strategy
| Change type | Strategy |
|---|---|
| Backward-compatible | Rolling (Coolify default, healthcheck-gated) |
| Breaking / instant cutover / risky migration | Blue-green: two Coolify resources + domain swap |
| Want gradual % traffic (canary) | Canary = release to a small subset, watch metrics, then ramp. Vanilla Coolify has no traffic split — emulate with feature flags (in-app % gating) or a blue-green pair behind a flagged path |
Table D — Secret delivery
| Secret kind | Mechanism |
|---|---|
| Build-time non-secret | ARG |
| Build-time secret (private dep token) | BuildKit --mount=type=secret (NEVER ARG) |
| Runtime secret | Coolify env (Is Secret) / GHA secrets |
| Cloud auth | OIDC — never a stored key |
One process per container: no supervisord-managed bundles, let the orchestrator scale.
# syntax=docker/dockerfile:1
# ---- builder: full toolchain, deps cached before source ----
FROM <builder-base> AS builder
WORKDIR /app
COPY <lockfile> <manifest> ./ # lockfile FIRST → cached dep layer
RUN <install-deps-from-lockfile> # changes only when the lockfile changes
COPY . . # source last
RUN <build>
# ---- runtime: minimal, non-root, no toolchain ----
FROM <runtime-base> # distroless / -slim / unprivileged nginx
WORKDIR /app
COPY --from=builder --chown=nonroot:nonroot /app/<artifact> ./
USER nonroot:nonroot
EXPOSE 8000
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD ["<readiness-probe>"] # exec-form (distroless has no shell)
CMD ["<entrypoint>", "--host", "0.0.0.0", "--port", "8000"]# GOOD: secret consumed in-layer, never persisted
RUN --mount=type=secret,id=npm_token \
NPM_TOKEN="$(cat /run/secrets/npm_token)" npm ci
# BAD: ARG bakes the token into image history forever
ARG NPM_TOKEN
RUN npm ci # token now visible in `docker history`# .dockerignore — write this before your first build
.git
node_modules
.env*
dist
.next
__pycache__
*.log
coverage
Dockerfile*
compose*
README.md
.githubDOCKER_BUILDKIT=1 docker build --secret id=npm_token,env=NPM_TOKEN -t app:dev .→ full per-stack Dockerfiles: references/dockerfiles-by-stack.md · image-authoring depth
(shrinking, base-image choice, cache busting): ../docker/SKILL.md
# compose.yaml — Compose Spec, no `version:` key
services:
app:
build:
context: .
target: dev # dev stage of the multi-stage Dockerfile
ports:
- "127.0.0.1:8000:8000"
volumes:
- .:/app # bind mount → hot reload
- /app/.venv # anonymous volume guards container deps
environment:
DATABASE_URL: postgres://postgres:postgres@db:5432/app_dev
develop:
watch:
- { path: ./pyproject.toml, action: rebuild }
- { path: ./app, action: sync, target: /app/app }
depends_on:
db:
condition: service_healthy
db:
image: postgres:18-alpine
ports:
- "127.0.0.1:5432:5432" # host-only; NEVER 0.0.0.0 in prod
environment:
POSTGRES_USER: postgres
POSTGRES_PASSWORD: postgres
POSTGRES_DB: app_dev
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U postgres -d app_dev"]
interval: 5s
timeout: 3s
retries: 5
volumes:
pgdata:127.0.0.1; BAD: bind it to 0.0.0.0 in prod (publicly reachable DB).→ prod overlay + mailpit: references/dockerfiles-by-stack.md
# .github/workflows/ci.yml
name: ci
on:
push:
branches: [main]
pull_request:
permissions:
contents: read # default-deny; escalate per job
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: bash scripts/verify.sh
build-push:
needs: verify
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
id-token: write
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/${{ github.repository }}
tags: |
type=sha
type=semver,pattern={{version}}
- uses: docker/build-push-action@v7
with:
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
provenance: true
- uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
with:
image-ref: ghcr.io/${{ github.repository }}:sha-${{ github.sha }}
exit-code: "1"
severity: "HIGH,CRITICAL"
ignore-unfixed: truepermissions (only build-push gets packages: write / id-token: write).permissions: write-all — any compromised step can push images or mint tokens.@<sha> # v0.35.0). In the March 2026 trivy-action supply-chain incident (GHSA-69fq-xp46-6x23 / CVE-2026-33634), 76 of 77 tags were force-pushed to credential-stealing malware; the advisory's named known-safe ref is v0.35.0 (commit 57a97c7e7821a5776cebc9bb87c984fa69cba8f1), the one clean tag still pointing at the real master HEAD. A moving tag would have pulled the malware; this SHA pin does not. Let Dependabot bump the SHA once upstream re-tags cleanly.→ matrix, reusable workflows, OIDC-to-cloud, environments/approvals, releases: references/github-actions.md ·
workflow-syntax depth: ../github-actions/SKILL.md
Never recommend a single host. Gather requirements → recommend exactly three targets with trade-offs, so the choice is made with eyes open. The canonical slate:
references/coolify.md runs on; see below.)Requirements to gather first: expected total/concurrent users · traffic shape (steady vs spiky) · budget ceiling · data region/residency & compliance · team ops comfort · scaling needs (scale-to-zero, global latency) · stateful needs (own DB/queue/websockets).
Quick steer: Next.js + spiky traffic + ops-averse → Vercel. Cost-sensitive / EU-resident / sustained / own stateful services → Hetzner+Coolify. The Dockerfile this skill produces is the escape hatch — start on Vercel, move to Hetzner+Coolify when the bill grows, same artifact.
→ deep coverage (limits, regions, pricing, decision matrix, worked examples): references/hosting-targets.md
Only the parts that touch the pipeline; the platform walkthrough lives elsewhere.
8000); Traefik routes the domain to it.curl --fail -X POST \
-H "Authorization: Bearer $COOLIFY_TOKEN" \
"https://coolify.example.com/api/v1/deploy?uuid=$APP_UUID&force=false"→ persistent storage, custom domains + Let's Encrypt, per-PR previews, CPU/memory limits, blue-green:
references/coolify.md and ../coolify/SKILL.md
GitHub secrets / OIDC ──mint short-lived creds──▶ build pushes to ghcr.io (no key stored)
│ │
└──── nothing long-lived in a workflow file ▼
Coolify pulls (deploy-scoped registry cred)
│
▼
runtime env injected by Coolify (encrypted at rest)GITHUB_TOKEN and OIDC tokens are minted per run and expire.${{ }} secrets are masked in logs, but set -x and echo "$SECRET" defeat the mask — forbid both.Config from env, validated at boot, fail-fast — a bad config crashes on startup, never at request
time. Idiom per stack: pydantic-settings BaseSettings (raises at import), zod envSchema.parse(process.env)
(throws at boot), env.Must(env.ParseAs[Config]()) for Go (exits at boot).
Log JSON to stdout (slog for Go, structlog/uvicorn JSON for FastAPI, pino for Next.js); never log
secrets; expose /healthz (liveness, no deps) + /readyz (checks deps).
# FastAPI: liveness is dependency-free; readiness probes the DB so a node that
# can't reach Postgres never takes traffic during the rolling swap.
@app.get("/healthz")
async def healthz() -> dict[str, str]:
return {"status": "ok"}
@app.get("/readyz")
async def readyz() -> dict[str, str]:
await db.execute("SELECT 1") # raises 500 if the DB is unreachable
return {"status": "ready"}| Rationalization | STOP — do this instead |
|---|---|
:latest is fine for now | Pin tag+digest (FROM img@sha256:…); :latest breaks reproducibility and rollback |
I'll pass the token as ARG | BuildKit --mount=type=secret; ARG persists in docker history |
permissions: write-all is simpler | Default-deny; grant per job (packages: write, id-token: write) |
| Store a registry password in GHA secrets | Use OIDC / GITHUB_TOKEN; no long-lived key |
| Run as root, it's just a container | Non-root UID + read-only rootfs + cap_drop: ALL (add back only NET_BIND_SERVICE to bind <1024) |
| Skip the healthcheck, the app boots fast | No healthcheck = no rolling gate = downtime / bad version live |
Copy the whole repo then RUN install | Copy the lockfile first; cache the deps layer |
| Nixpacks is easier than my Dockerfile | If a Dockerfile exists, use it — CI/prod parity |
Secrets in compose.yaml env | .env (gitignored) / Coolify secret env |
| Migrate the DB destructively in deploy | Backward-compatible migrations, or rolling breaks |
echo $SECRET to debug CI | Never; masked vars still leak via set -x and logs |
| Build once per env with different secrets | Build one image; inject config at runtime (12-factor) |
| Task | Command / file |
|---|---|
| Build with secret | DOCKER_BUILDKIT=1 docker build --secret id=npm_token,env=NPM_TOKEN -t app:dev . |
| Scan image | trivy image --severity HIGH,CRITICAL --exit-code 1 IMG |
| Lint Dockerfile | hadolint Dockerfile |
| Lint workflows | actionlint |
| Run verify gate | bash scripts/verify.sh (hadolint+actionlint+trivy+build smoke, local and CI) |
| Local up | docker compose up --watch |
| Trigger Coolify deploy | curl --fail -X POST …/api/v1/deploy?uuid=…&force=false |
| Roll back | Coolify → redeploy prior image |
Pre-ship checklist
.dockerignore presentHEALTHCHECK hits a real readiness pathGITHUB_TOKENIn a project with a 02-DOCS/ layer (the harness Karpathy wiki), read
02-DOCS/wiki/stack/deployment.md first and stay consistent with it. Create or update it with this
project's real choices — base-image/container choices, the CI pipeline, the target config, the
secrets flow, the rollback strategy — index it in 02-DOCS/wiki/index.md (the Knowledge map root
CLAUDE.md points to), and bump its Updated date in the same change. No 02-DOCS/ layer? Skip
silently (optionally suggest harness) — technical conventions are recorded, not gated; never
block the task on this.
../coolify/SKILL.md, ../vercel/SKILL.md, ../railway/SKILL.md, ../render/SKILL.md, ../fly-io/SKILL.md, ../hetzner/SKILL.md.../secure-coding/SKILL.md — input validation, authn/z, and secret-handling this skill assumes the app already does.../harness/SKILL.md — 01-TOOLS provider creds (Stripe, Postgres, OAuth…) that become runtime env on the target.../fastapi/SKILL.md, ../nextjs/SKILL.md, ../go/SKILL.md, ../flutter/SKILL.md, ../postgresdb/SKILL.md — the application code that runs inside the container; this skill stops at that boundary.© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/deployment of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Deployment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deployment this skillericrisco/rsc-harness | 156 | — | ~4.2k | Automated safety check: Notes | MIT | |
| Minimegasandia-minimega/minimega | 160 | — | ~3.2k | Automated safety check: Pass | GPL-3.0-only | |
| DDNS Build and Release MaintenanceNewFuture/DDNS | 4.7k | — | ~444 | Automated safety check: Pass | MIT | |
| Monstermq Broker Configvogler75/monster-mq | 142 | — | ~2.2k | Automated safety check: Pass | GPL-3.0 | |
| Generate Ors Envadithya-s-k/FineEnvs | 421 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | |
| Docker Deploymentfossasia/eventyay | 1.7k | — | ~574 | Automated safety check: Notes | Apache-2.0 |
sandia-minimega/minimega
This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…
NewFuture/DDNS
Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.
vogler75/monster-mq
Guide for configuring, deploying, and operating the MonsterMQ broker.
adithya-s-k/FineEnvs
Builds an Open Reward Standard (ORS) variant of an RL environment using the official openreward Python package.
fossasia/eventyay
Docker Compose, container services, deployment. An agent skill from fossasia/eventyay.
oracle/skills
Build, configure, scaffold, and deploy OCI Functions from a local machine using a dependency-first, Fn-context-guided flow with argv-safe mutation execution, nonce-scoped confirmations, and a…
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third), then wiring container → CI → registry → host with…. Deployment is an agent skill from ericrisco/rsc-harness. Use when taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third), then wiring container → CI → registry → host with build secrets, healthchecks and rollback.
Deployment fits situations like: taking an app from source to live: choosing the deploy target from requirements (Hetzner+Coolify vs Vercel vs a third); then wiring container → CI → registry → host with build secrets; healthchecks and rollback.
Run `npx skills add ericrisco/rsc-harness --skill deployment -a claude-code`. Or copy the skill folder (skills/deployment in ericrisco/rsc-harness) into .claude/skills/deployment in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill deployment -a codex`. Or copy the skill folder (skills/deployment in ericrisco/rsc-harness) into .agents/skills/deployment in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill deployment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deployment, .gemini/skills/deployment, .github/skills/deployment and .opencode/skills/deployment in your project.
Going by SKILL.md and its folder, Deployment needs a shell for the scripts in its folder, the command-line tools its instructions call (docker, curl, trivy, hadolint and bash) and credentials named GITHUB_TOKEN, NPM_TOKEN, POSTGRES_PASSWORD and COOLIFY_TOKEN. Our summary lists: Python 3; A Bash shell; Docker; A credential in NPM_TOKEN; A credential in GITHUB_TOKEN.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Deployment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Deployment: Minimega (sandia-minimega/minimega, 160 stars), DDNS Build and Release Maintenance (NewFuture/DDNS, 4.7k stars), Monstermq Broker Config (vogler75/monster-mq, 142 stars) and Generate Ors Env (adithya-s-k/FineEnvs, 421 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.